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DETAILED ACTION 

1. Claims 1-19 have been examined. 

Claim Objections 

2. Claims 12 and 19 are objected to because of the following 
informalities: "each of a plurality of electronic documents are " (line 2). 
Appropriate correction is required. 

Claim Rejections - 35 USC §101 

3. 35 U.S.C. 101 reads as follows: 

Whoever invents or discovers any new and useful process, machine, manufacture, or 
composition of matter, or any new and useful improvement thereof, may obtain a patent 
therefor, subject to the conditions and requirements of this title. 

4. Claims 13-19 are rejected under 35 U.S.C. 101. The claims are 
directed to a computer readable medium that provides instruction. Such a 
computer readable medium includes carrier waves (see Specification, 
paragraph 0090), which does not fall within one of the four statutory classes 
of § 101. Please refer to Annex IV of Interim Guidelines for Examination of 
Patent Applications for Patent Subject Matter Eligibility , 1300 Off. Gaz. Pat. 
Office 142 (Nov. 22, 2005) (Patent Subject Matter Eligibility Interim 
Guidelines). 
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Claim Rejections - 35 USC §112 

5. The following is a quotation of the second paragraph of 35 U.S.C. 112: 

The specification shall conclude with one or more claims particularly pointing out and 
distinctly claiming the subject matter which the applicant regards as his invention. 

6. Claims 6-19 are rejected under 35 U.S.C. 112, second paragraph, as 
being indefinite for failing to particularly point out and distinctly claim the 
subject matter which applicant regards as the invention. Regarding claim 6, 
it recites the limitation "the electronic document" in line 6. There is 
insufficient antecedent basis for this limitation in the claim. Claim 13 is 
rejected on the same basis as claim 1. Claims that are not specifically 
addressed are rejected by virtue of their dependency. For examination 
purpose, the limitation is interpreted as "an electronic document". 

7. Claims 1-5 are rejected under 35 U.S.C. 112, second paragraph, as 
being incomplete for omitting essential steps, such omission amounting to a 
gap between the steps. See MPEP § 2172.01. Regarding claim 1, the 
omitted step is: limiting access to electronic documents as stated in the 
preamble. Claims that are not specifically addressed are rejected by virtue 
of their dependency. 
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Claim Rejections - 35 USC §102 

8. The following is a quotation of the appropriate paragraphs of 35 
U.S.C. 102 that form the basis for the rejections under this section made in 
this Office action: 

A person shall be entitled to a patent unless - 

(b) the invention was patented or described in a printed publication in this or a foreign country 
or in public use or on sale in this country, more than one year prior to the date of application 
for patent in the United States. 

(e) the invention was described in (1) an application for patent, published under section 
122(b), by another filed in the United States before the invention by the applicant for 
patent or (2) a patent granted on an application for patent by another filed in the United 
States before the invention by the applicant for patent, except that an international 
application filed under the treaty defined in section 351(a) shall have the effects for 
purposes of this subsection of an application filed in the United States only if the 
international application designated the United States and was published under Article 
21(2) of such treaty in the English language. 

9. Claims 1-9, 11-16 and 18-19 are rejected under 35 U.S.C. 102(e) as 
being anticipated by Leser et al. (2005/0028006). 

Regarding claims 1-2, Leser discloses a method comprising: creating a 
process-driven security policy having a plurality of states, with each of the 
states having a different set of access restrictions (figures 1-5; paragraphs 
0096, 0106); associating an identifier to the process-driven security policy, 
i.e., research/review/publish policy (fig. 1, element 14; figures 2-5); and 
making the identifier available to certain of users or groups of users (fig. 15, 
element 124). 

Regarding claims 3-5, Leser further discloses that the process-driven 



security policy is provided or part of a document security system in which 



Application/Control Number: 10/677,049 Page 5 

Art Unit: 2132 

the identifier is assigned to a document(s) when the document is created 
(fig. 6, elements 22-23; paragraphs 0146, 0194-0195). 

Regarding claims 6 and 13, Leser discloses a method comprising: 
providing at least one process-driven security policy from a server machine 
to a client machine (fig. 17, steps 140-142), the process-driven security 
policy having a plurality of states associated therewith (fig. 1, elements 14; 
figures 2-5; paragraph 0106); and associating an electronic document with 
at least one of the states of the process-driven security policy (i.e., 
associating new document with a security policy having a plurality of states) 
to impose access restrictions on an electronic document, the access 
restrictions being dependent on the at least one of the states of the process- 
driven security policy (fig. 17, steps 144-147). 

Regarding claims 7-9 and 14-16, Leser further discloses that the state 
of the process-driven security policy for a document changes when the 
document is sent or received by a certain user (or his/her computer) (figures 
2-5). 

Regarding claims 11 and 18, Leser further discloses that not every 
document is associated with the process-driven security policy (paragraph 
0151). 
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Regarding claims 12 and 19, Leser further discloses that a plurality of 
electronic documents are protected by the process-driven security policy 
(paragraphs 0097, 0146). 

10. Claims 1-5 are rejected under 35 U.S.C. 102(e) as being anticipated 
by Venkatesan et al. (6,801,999). 

Regarding claim 1, Venkatesan discloses a method comprising: 
creating a process-driven security policy, having a plurality of states, with 
each of the states having a different set of access restrictions (i.e., 
generating a license indicating a content can be accessed a certain number 
of times or for a certain time period) (col. 2, lines 55-67; col. 30, lines 7- 
41); associating an identifier to the process-driven security policy (i.e., 
including the content name/product identification PID in the license) (col. 5, 
line 45-59; fig. 11, step 1122; fig. 12, element 1230) and making the 
identifier available to certain of users or groups of users to the process- 
driven security policy (i.e., including the PID in the header of a file for 
download) (fig. 10, elements 1012, 1014, 1015). 

Regarding claims 3-5, Venkatesan further discloses that the process- 
driven security policy is provided or part of a document security system (i.e., 
a digital right management (DRM) system) (col. 10, lines 49-61) and that 
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when a document(s) (i.e., content) is created, the identifier of the document 
(i.e., the PID) is assigned to the document (fig. 10). 

11. Claims 6-19 are rejected under 35 U.S.C. 102(b) as being anticipated 
by Downs et al (6,226,618). 

Regarding claims 6, 11, 13 and 18, Downs discloses a method 
comprising: providing at least one process-driven security policy from a 
server machine to a client machine, the process-driven security policy 
having a plurality of states associated therewith (i.e., a license indicating a 
content can be accessed a certain number of times or for a certain time 
period) (col. 6, lines 36-67; col. 7, lines 1-10, lines 41-65; col. 10, lines 60- 
63; col. 21, lines 43-63; col. 59, lines 7-66); and associating an electronic 
document with at least one of the states of the process-driven security policy 
to impose access restrictions on an electronic document, the access 
restrictions being dependent on the at least one of the states of the process- 
driven security policy (i.e., embedding usage conditions in the content for 
controlling access to content) (col. 59, lines 7-66; col. 63, line 61 - col. 64, 
line 34; col. 82, lines 6-22) 

Regarding claims 7-9 and 14-16, Downs further discloses that 
subsequently changing the state of the process-driven security policy (i.e., 
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each time the user access the content or each day has passed) (col. 59, 
lines 7-66) 

Regarding claims 10 and 17, Downs further discloses that the content 
includes security information, which includes at least an indication of the 
state of the process-driven security policy for the content (col. 82, lines 6- 
22). 

Regarding claims 12 and 19, Downs further discloses that the content 
is an album containing multiple songs (col. 52, lines 59-64). 



Claim Rejections - 35 USC §103 

12. The following is a quotation of 35 U.S.C. 103(a) which forms the basis 
for all obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or 
described as set forth in section 102 of this title, if the differences between the subject 
matter sought to be patented and the prior art are such that the subject matter as a 
whole would have been obvious at the time the invention was made to a person having 
ordinary skill in the art to which said subject matter pertains. Patentability shall not be 
negatived by the manner in which the invention was made. 

13. Claims 10 and 17 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Leser as applied to claims 6 and 13 above, and further in 
view of Martin et al. (2003/0217264). Leser does not disclose that the 
electronic document includes security information, and the security 
information includes an indication of the state of the process-driven security 



policy for the electronic document. Martin discloses a method and system 
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for protecting electronic document using a process-driven security policy, 
i.e., state-based access control policy, wherein the electronic document is 
processed by a user at one state of a workflow and then transferred to 
another user at the next state of the workflow (Abstract; fig. 1, elements 8- 
9; paragraph 0015). Martin further discloses that the electronic document 
includes a signature of the document signed by the user at each state before 
the signed document is transferred to the next state (fig. 4, steps 70-72; 
paragraph 0022). It would have been obvious to one of ordinary in the art 
at the time the invention was made to modify Leser method such that the 
electronic document includes a signature of the document signed by the user 
at each state before the signed document is transferred to the next state, as 
taught by Martin. Using the signature, the user at the next state would be 
able to verify that the electronic document had not been altered from the 
time the user at the previous state signed the electronic document 
(paragraph 0022). 

14. Claim 2 is rejected under 35 U.S.C. 103(a) as being unpatentable over 
Venkatesan. Venkatesan discloses that the content can be of any 
format/type, i.e., a graphic, image, audio or video file for passive content or 
an executable file for active content (col. 10, lines 2-16). Venkatesan does 
not disclose that the content name (i.e., the PID) include a file name 
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extension (i.e., a suffix to the name of a file to show its format). Official 
Notice is taken that using a file name extension is well known in the art. It 
would have been obvious to include a file name extension in the PID in 
Venkatesan so that a user(s) could identify the format/type of the content. 



Double Patenting 

15. The nonstatutory double patenting rejection is based on a judicially 
created doctrine grounded in public policy (a policy reflected in the statute) 
so as to prevent the unjustified or improper timewise extension of the "right 
to exclude" granted by a patent and to prevent possible harassment by 
multiple assignees. A nonstatutory obviousness-type double patenting 
rejection is appropriate where the conflicting claims are not identical, but at 
least one examined application claim is not patentably distinct from the 
reference claim(s) because the examined application claim is either 
anticipated by, or would have been obvious over, the reference claim(s). 
See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In 
re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 
759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 
937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 
(CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 
1969). 

A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) 
or 1.321(d) may be used to overcome an actual or provisional rejection 
based on a nonstatutory double patenting ground provided the conflicting 
application or patent either is shown to be commonly owned with this 
application, or claims an invention made as a result of activities undertaken 
within the scope of a joint research agreement. 

Effective January 1, 1994, a registered attorney or agent of record 
may sign a terminal disclaimer. A terminal disclaimer signed by the assignee 
must fully comply with 37 CFR 3.73(b). 

16. Claims 6-7, 12-14 and 19 are provisionally rejected on the ground of 
nonstatutory obviousness-type double patenting as being unpatentable over 
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claims 21-22, 24 and 28 of copending Application No. 10/676474. Although 
the conflicting claims are not identical, they are not patentably distinct from 
each other because , with one exception, all of the limitations in the instant 
claims are present in the corresponding claims of Application '474. The one 
exception is that whereas the instant claims use a process-driven security 
policy, the '474 claims use a reference to the process-driven security policy, 
However, having a reference to an object (e.g., a pointer, link, URL, etc.) is 
functionally equivalent to having the object itself. Therefore, using a 
reference to an object is an obvious variation of using the object itself, and 
is not a patentable difference between the two set of claims... 

This is a provisional obviousness-type double patenting rejection 
because the conflicting claims have not in fact been patented. 

Conclusion 

17. The prior art made of record and not relied upon is considered 
pertinent to applicant's disclosure. 

Botha et al., "Separation of Duties for Access Control Enforcement in 
Workflow Environments" 

Any inquiry concerning this communication or earlier communications 
from the examiner should be directed to Minh Dinh whose telephone number 
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is 571-272-3802. The examiner can normally be reached on Mon-Fri: 
10:00am-6:30pm. 

If attempts to reach the examiner by telephone are unsuccessful, the 
examiner's supervisor, Gilberto Barron can be reached on 571-272-3799. 
The fax phone number for the organization where this application or 
proceeding is assigned is 571-273-8300. 

Information regarding the status of an application may be obtained 
from the Patent Application Information Retrieval (PAIR) system. Status 
information for published applications may be obtained from either Private 
PAIR or Public PAIR. Status information for unpublished applications is 
available through Private PAIR only. For more information about the PAIR 
system, see http://pair-direct.uspto.gov. Should you have questions on 
access to the Private PAIR system, contact the Electronic Business Center 
(EBC) at 866-217-9197 (toll-free). If you would like assistance from a 
USPTO Customer Service Representative or access to the automated 
information system, call 800-786-9199 (IN USA OR CANADA) or 571-272- 
1000. 

HP 

Minh Dinh 
Examiner 
Art Unit 2132 
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